Sign inSign up
WordPress

dhi.io/wordpress

WordPress 6.9.9 (php8.5-fpm, fips)

CIS
FIPS
STIG
linux/arm64
debian 13
Tags:

6.9.9-debian-php8.5-fpm-fips, 6.9.9-debian13-php8.5-fpm-fips, 6.9.9-php8.5-fpm-fips

Index digest:

sha256:91d84e0151b147a2af8640ba7091307ca708146b3cfd55dc3d462f50bbe6a650

Manifest digest:

sha256:00b35f939b0dc3d2568583f8d02417e1e3903aff4eedc2bc5136c37195ba35e4

Size

113.29 MB

Last pushed

22 hours ago

Vulnerabilities

0
1
1
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wordpress:6.9.9-debian-php8.5-fpm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wordpress:6.9.9-debian-php8.5-fpm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wordpress@sha256:b40c688d5d24008ad6afc8863d41e964f675009fac90fe40c708119082ac08a2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wordpress@sha256:b51706133bfd1bc7d5b78bcc39c531256527972823fc3b9f1acfa047a9f5ece3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wordpress@sha256:80a35def326a6941cff12b2c8d2094e736ec0f8f86445fd1299f50273ec1d86b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wordpress@sha256:6d1dfb9a1a9fabf26622af6609f2d201e416fe1be31633fb6f6f5d405675add5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wordpress@sha256:5ca6023cf00a055c89249804cc6ca62e7bdd8cdbdcf72209a8e521c02eec1d6b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wordpress@sha256:e68905534fb3b6afac3e8dba782610ee46c70854339e6b2587fb30ef67cd38fa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wordpress@sha256:d1a81c4051a3419c262af61b3ae4bdc2e19e8db2d74c93946a0e2c0291ddf811
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wordpress@sha256:6f453060a5134de5c9bffb164326678fc25c2cef23c17dfcc29c3e83a6b4e16e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wordpress@sha256:1905644663985ae658efa371390a9b1c57028eacf9395e7068e5ef8bf63b43b2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wordpress@sha256:cd6774538747a4487b11382b2d75307f209b15fc09812e182f6eae388749dd25
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wordpress@sha256:4de994d77638a6ae2d1c50d441b491ea3e687bd209e00b63066d47573fedcdc5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wordpress@sha256:b98b4adf67256e68c507e950563776789f24f655dc7e0f5369a8c7452dbc21a6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wordpress@sha256:7146d6864f72d1898706db0f43596b8f0b0ac8818ff9d6e744b0b5837ed5d304
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wordpress@sha256:c0ddc0eb76d9ebcb3ab6741255d08b10920eceb364e8ce0188c32e1fd06b94c5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wordpress@sha256:6900f7d778304c9550ea3d9c583ebebb125c5a3c0df5506e0589c184354d055c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wordpress@sha256:a5dd3c6e9d04be880f8a1fc5afa81a733ce37c6b81e01982ada94d4a1d5f17ab
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wordpress@sha256:5e2f8c11f012df2bbf9aab6ba5f0df1ab6e7dd686855f7d712044453b5f8c604